VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 111 of 160
  • CVE-2025-49727HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1252HigMay 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from…

  • CVE-2025-27478HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21414HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2025-21184HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2024-43522HigOct 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

  • CVE-2024-38170HigAug 13, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-38032HigJul 9, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Xbox Remote Code Execution Vulnerability

  • CVE-2023-51596HigMay 3, 2024
    risk 0.46cvss 7.1epss 0.02

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2024-33429HigMay 1, 2024
    risk 0.46cvss 7.1epss 0.01

    Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.

  • CVE-2024-0156HigMar 4, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.

  • CVE-2022-36764HigJan 9, 2024
    risk 0.46cvss 7.0epss 0.00

    EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

  • CVE-2022-36763HigJan 9, 2024
    risk 0.46cvss 7.0epss 0.00

    EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

  • CVE-2023-47118HigDec 20, 2023
    risk 0.46cvss 7.0epss 0.00

    ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-47038HigDec 18, 2023
    risk 0.46cvss 7.0epss 0.01

    A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.

  • CVE-2023-4264HigSep 27, 2023
    risk 0.46cvss 7.1epss 0.01

    Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

  • CVE-2023-4504HigSep 21, 2023
    risk 0.46cvss 7.0epss 0.01

    Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

  • CVE-2023-21406HigJul 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid…

  • CVE-2023-33152HigJul 11, 2023
    risk 0.46cvss 7.0epss 0.01

    Microsoft ActiveX Remote Code Execution Vulnerability

  • CVE-2023-28218HigApr 11, 2023
    risk 0.46cvss 7.0epss 0.12

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability